All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Lakewatch's competitive protection is thin and mostly unproven. Its one real advantage is placement. Lakewatch runs detection inside the Databricks platform where a customer already keeps its data, so leaving means rebuilding detection workflows and analyst practices around another engine, while the telemetry stays in customer-controlled open formats. Everything else is easier to copy. Its detection rules are expressed as code, outside frontier models help power its alert triage, and its customers keep their own logs. The hard part to copy is real-time threat detection at petabyte scale. The public record shows no private dataset Lakewatch owns and no mandate specific to it. In private preview, even placement is a head start, not a proven barrier.
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Lakewatch names the SOC team drowning in telemetry it cannot afford to keep, and independent coverage repeats the pain, that cost forces teams to discard up to 75 percent of their data while mean time to exploit collapses. The quantified figures trace to vendor-marshaled secondary sources rather than independent measurement, so the pain is present but unproven at the level claimed. [s2, s4, s5] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The launch materials detail concrete mechanisms: Genie for natural-language hunting and detection authoring, Agent Bricks for custom triage agents, detection-as-code in YAML and Python with backtesting, and automated OCSF normalization. Held at present-but-unproven because no external validation point exists yet, with the line in private preview and no public docs portal, third-party evaluation, or customer technical writeup for it. [s1, s2, s5] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Independent coverage places Lakewatch in a category the market is actively rebuilding, naming Google's Agentic SOC, CrowdStrike's Charlotte AI, and SentinelOne's Purple AI as concurrent agentic-SOC entries, and the launch cites regulatory drivers such as NIS2 and DORA. The enabler is LLM-driven attacks that the cited sources put at a mean time to exploit of 1.6 days in 2026, down from 23.2 days a year earlier. Held below 5 because the demand signals are launch-concurrent rather than a settled buyer pattern. [s5, s3, s2] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Lakewatch folds in SiftD.ai, founded by the creator of Splunk's Search Processing Language and lead architects of its search stack, which independent coverage frames as detection-engineering credibility that would take years to build organically, plus Antimatter's UC Berkeley researchers for agent authorization. That is verifiable in-domain pedigree in the exact category, multiply sourced. Held below 5 because the individuals are unnamed in the cited coverage and the acquisitions were announced at launch, so the combined team has no shipped track together yet. [s6, s5, s2] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Lakewatch launched with two named preview customers, Adobe and Dropbox, and an ecosystem of security and delivery partners including Okta, Zscaler, and Wiz. Held at the named-reference level because those are private-preview references without disclosed scale, and the parent platform's reach is distribution into the buyer rather than proven adoption of this line. [s2, s6, s5] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The line shipped a product, an open partner ecosystem, and two folded-in acquisitions in a single launch, which is visible output. Held at the default because there is no line-level revenue, cost, or headcount to confirm output per dollar, and the parent's balance sheet is not used to stand in for it. [s2, s3] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Independent outlets placed Lakewatch in the decades-old SIEM budget line without vendor coaching, describing it plainly as a Security Information and Event Management system, and the agentic-SIEM cut is one several vendors now share. Held below 5 because Lakewatch enters an established category as a new arrival rather than defining or leading it. [s4, s6, s5] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Running the SIEM on the lakehouse where a customer's data already sits, under Unity Catalog governance, creates real integration friction, but agentic triage is a capability every incumbent SIEM is shipping, and the open-format design lets a customer keep the data and point another engine at it. No structural moat specific to the line is yet evidenced. [s5, s2] |
Lakewatch sells to the security operations team whose telemetry has outgrown what a traditional SIEM can affordably hold. Databricks argues that high ingestion costs force teams to discard up to 75 percent of their data, exactly when attackers turn to automation, and independent coverage repeats that framing.
The launch times the problem to machine-speed attacks. Databricks marshals sources that put mean time to exploit at 1.6 days in 2026, down from 23.2 days a year earlier, and argues that human-paced SOC workflows cannot keep up. That message targets the SOC leader who measures staffing and triage throughput, a wider audience than the detection engineer.
The pain is clearly stated but the quantification is vendor-marshaled. The specific figures come from secondary blog and index sources the launch cites rather than independent measurement, so a buyer sees a well-framed problem that rests on the vendor's own evidence chain. [s2, s4, s5]
Lakewatch runs security detection directly on the Databricks lakehouse rather than in a separate SIEM store. Built on Unity Catalog, security telemetry sits alongside HR, collaboration, and application data, so an analyst can correlate across any source without duplicating or moving it.
Agents are the differentiating layer. Genie authors net-new detections from threat intelligence, tunes rules to cut false positives, and answers natural-language hunting questions across petabytes, while Agent Bricks builds custom triage agents, both running on Anthropic's Claude models. Detection-as-code defines rules in YAML with SQL or Python, backtested against history and deployed through CI/CD.
Open formats carry the economics. Lakewatch stores full-fidelity telemetry in the customer's own cloud storage using Delta Lake or Apache Iceberg and normalizes sources to OCSF, which Databricks says decouples storage from compute and cuts total cost up to 80 percent. No external evaluation confirms the capability set yet, with the line in private preview. [s1, s2, s5]
Lakewatch enters a SIEM market that vendors are rebuilding around agents. Independent coverage names Google's Agentic SOC, CrowdStrike's Charlotte AI, and SentinelOne's Purple AI as concurrent entries, so Lakewatch competes for the same detection budget as both legacy incumbents and new agentic challengers.
The entry point is the security lakehouse. Databricks argues that running detection where the data already lives, on open formats a customer controls, beats both proprietary legacy SIEMs priced by ingestion and overlay agents that lack native access to the underlying data. Panther, the AI SOC platform Databricks agreed to acquire in June 2026, folds that same data-lake-plus-detection thesis into the portfolio.
The position carries its own exposure. Agentic triage is the feature every SIEM vendor is shipping, and the open-format design that undercuts incumbents on lock-in also lowers Lakewatch's own switching cost, so Lakewatch competes on platform gravity rather than a unique capability. [s5, s2, s3, s7]
Lakewatch reaches buyers through the Databricks platform rather than a standalone motion. A customer already running the lakehouse can bring security data onto it, so the line travels through channels the platform already has, though that is reach rather than proven adoption.
The launch named two preview customers and a partner ecosystem. Adobe and Dropbox are cited as private-preview users, and the Open Security Lakehouse Ecosystem lists security and delivery partners including Okta, Zscaler, Wiz, Cribl, and Deloitte. Anthropic both powers the product with Claude and runs its own security lakehouse on Databricks.
The traction is announcement-stage. Lakewatch is in private preview with no quantified paid adoption or line-level revenue disclosed, so its adoption cannot yet be separated from the platform it ships inside, and the named partners are vendor interest rather than buyer proof. [s2, s6, s5]
Lakewatch's detection-engineering credibility arrives largely through acquisition. Databricks folded in SiftD.ai, founded by the creator of Splunk's Search Processing Language and lead architects of its search stack, which independent coverage frames as detection expertise that would take years to build organically.
A second acquisition adds agent security. Antimatter, built by UC Berkeley researchers, brought a provably secure approach to authentication and authorization for AI agents, which fits the defensive-agent design at the center of Lakewatch.
The combined team is newly assembled. Both acquisitions were announced at launch and the specific individuals are unnamed in the cited coverage, so the domain pedigree is verifiable but the group has no shipped product together yet, on top of Databricks' own data-and-AI engineering depth. [s6, s5, s2]
Lakewatch inherits the trust posture of the platform it runs on. Security data stays in the customer's own cloud storage under Unity Catalog governance, with fine-grained access control at table, row, column, and attribute levels and full audit, so adopting Lakewatch extends an existing trust boundary rather than adding a new custodian.
The design speaks to compliance-driven buyers. Databricks positions long-term, cost-effective retention as a way to meet mandates such as NIS2 and DORA, and the open formats keep telemetry portable rather than locked to a proprietary store.
The readiness gap is maturity. Lakewatch is in private preview working toward broader availability, so a buyer is evaluating a control plane that is shipping and announced rather than proven in production, and the autonomous agents' behavior in live SOC workflows has no independent track record yet. [s1, s2, s3]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Splunk | competes with | The incumbent SIEM, now part of Cisco, that Lakewatch positions against on ingestion-based cost and legacy architecture. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| CrowdStrike | competes with | Falcon Next-Gen SIEM and the Charlotte AI agentic SOC contest the same detection budget from the endpoint-platform side. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Microsoft | competes with | Microsoft Sentinel with Security Copilot is the cloud-SIEM incumbent bundling agentic triage into a platform buyers already own. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
| Elastic | competes with | Elastic Security runs SIEM and XDR on a search-and-data platform, the closest architectural analog to the security-lakehouse approach. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Hunters | competes with | Cloud-native SIEM built on an OCSF data lake with automated investigation, a direct next-gen-SIEM peer. | N/AWe scored these companies at different scopes, so the totals measure different things. |
Add analyzed competitors to compare them side by side with Lakewatch.
A closer look at this line's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
Lakewatch keeps little when a customer leaves, and the reasons are plain. Its detection rules are expressed as code, outside frontier models help power the alert triage, and customers keep their security logs in open formats another engine can read in place. What leaving costs is rebuild work: detection workflows, CI/CD integration, and analyst practices re-created on another tool while the telemetry itself stays put. The hard part to rebuild is real-time threat detection at petabyte scale, which is technically difficult to reproduce. The public record identifies no private dataset Lakewatch owns and no compliance mandate specific to it. In private preview, even that platform advantage is a head start rather than a proven barrier.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers get security software they configure and run, a SIEM with detection agents and no published billing meter, rather than a managed judgment or accountability outcome they could not staff in-house. That is the software-product level, the same delivery as the cloud-SIEM peers. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Detection-as-code wired into CI/CD and security data consolidated on the lakehouse under Unity Catalog create real reabsorption cost, but the open-format design keeps telemetry in the customer's own Delta Lake or Iceberg storage, so a customer could repoint another engine at the same data, which caps the moat at the cloud-SIEM peer level. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Lakewatch helps buyers meet mandates such as NIS2 and DORA through retention and governance, but that is enablement bundled into the platform rather than a federal authorization or mandate that requires the product, so it does not lock a buyer in. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Real-time detection and multi-step agentic investigation over petabyte-scale, multi-modal telemetry on a governed lakehouse is genuinely hard engineering, the same order of complexity as the cloud-SIEM peers, and the Splunk-search lineage from SiftD.ai underlines the specialized depth involved. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The named preview buyers, Adobe and Dropbox, are large technology enterprises with serious procurement, but government and regulated-sector buyers are absent from the record, and Databricks' broader install base is parent reach rather than the line's own proven buyer, so it scores with the cloud-first cluster. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Lakewatch is a security application on the lakehouse: other tools feed it telemetry through the open ecosystem, and analysts work inside it, but the reviewed record shows no other security product that depends on Lakewatch to run, so it holds the platform-with-application-features level rather than the infrastructure level. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The detection content is code a rival can rebuild, outside frontier models help power the agents, and the customer's telemetry lives in the customer's own open-format storage rather than a Lakewatch-owned cross-customer corpus, so no non-public data asset that a new entrant could not assemble appears in the record while the line is in preview. |
Databricks aims Lakewatch at the enterprise SOC already generating more telemetry than a legacy SIEM can affordably hold. The launch names Adobe and Dropbox, large technology enterprises, as early preview users.
The buyer is the security operations leader, a more explicit security persona than the data and platform teams that Databricks' governance lines address. The message speaks to teams measuring triage throughput and analyst time against machine-speed attackers, and the ecosystem of security partners signals a deliberate reach into the security organization.
An existing-customer skew is an architectural hypothesis, not demonstrated reach. Lakewatch's economics assume a customer will consolidate security data on the lakehouse, so the natural early buyer would already run the platform, and the cited pages do not document reach beyond that base while the line is in private preview.
Lakewatch's advantage is placement, not a novel model. Running detection on the lakehouse lets agents reach security, IT, and business data in one governed store, so investigations correlate across sources that a standalone SIEM would have to ingest and duplicate first.
Defensive agents are the marketed capability. Security agents author and tune detections, Genie answers natural-language hunting questions, Agent Bricks builds multi-step triage agents, and the stack runs on Anthropic's Claude models, which the launch frames as fighting machine-speed attackers with machine-speed defense.
The model layer offers no moat of its own. Anthropic's Claude models help power the agents under a partnership, and nothing in the record shows that access is exclusive, so Lakewatch's edge has to come from what its agents can reach, the unified lakehouse and the detection code, rather than from model quality, and that edge is unproven while the product is in preview.
Databricks sells Lakewatch as an extension of the platform rather than a separate product. A customer already on the lakehouse can enable security workloads on it. The cited record documents that delivery model but not Lakewatch's sales cycle, activation, or line-level conversion.
The launch leaned on an ecosystem and named references. Adobe and Dropbox anchor the customer proof, and the Open Security Lakehouse Ecosystem recruited security and delivery partners including Okta, Zscaler, Wiz, Cribl, Proofpoint, and Deloitte to normalize telemetry and deliver services.
The proof is early. Lakewatch is in private preview with no disclosed paid adoption or line-level revenue, so its traction cannot yet be separated from the platform, and the partner roster is vendor interest ahead of buyer outcomes.
Databricks markets Lakewatch on lakehouse economics rather than an ingestion meter. Databricks decouples storage from compute, so a customer stores full-fidelity telemetry in its own cloud object storage, and the company says the decoupled model cuts total cost of ownership up to 80 percent against legacy SIEMs. The cited pages publish no Lakewatch billing meter of its own.
The unit attacks the incumbent pain directly. Legacy SIEMs charge by data ingested, which pushes teams to drop logs, so a model that removes the per-byte penalty is the central cost argument Lakewatch makes to buyers.
The claim is vendor-stated and unpriced in public. Databricks has not published Lakewatch list pricing, the 80 percent figure carries no public methodology, and the preview stage leaves the real economics unconfirmed by independent buyers.
Databricks delivers Lakewatch as a managed layer on the platform enterprises already operate. Security data lands in the customer's own cloud storage in open formats, normalized to OCSF through the platform's ingestion, so adopting Lakewatch adds a security workload rather than a new system to stand up.
Detection ships as code. Rules are defined in YAML with SQL or Python, backtested against historical data, and deployed through CI/CD pipelines, which brings version control and testing to the detection lifecycle.
The operational record is short. Lakewatch is in private preview working toward broader availability, so its behavior at production scale and the reliability of autonomous triage in live SOCs are not yet independently established.
Lakewatch's trust story depends on customer-owned data and platform governance. Telemetry stays in the customer's cloud storage under Unity Catalog, with access control at table, row, column, and attribute levels and full audit, so the buyer grants less custody than a proprietary SIEM would require.
The design targets compliance retention. Databricks positions cost-effective, multi-year retention as a way to meet mandates such as NIS2 and DORA, and open formats keep the data portable rather than locked to a proprietary store.
The autonomous layer is the open question. Agents that author detections and triage alerts act inside the SOC, the cited record does not specify whether human approval of AI-authored detections is required, and the private-preview stage means the agents' judgment has no independent production track record.
Lakewatch is a platform play built on a bigger platform. It runs on the Databricks lakehouse and Unity Catalog, so Databricks can offer it to enterprises already running that platform, while adding a security-specific partner layer. That parent reach is a potential cross-sell rather than demonstrated Lakewatch adoption, which rests on Adobe and Dropbox's preview use and stays early in private preview.
The Open Security Lakehouse Ecosystem is the deliberate reach. Databricks recruited security, data-pipeline, and delivery partners, among them Okta, Zscaler, Wiz, Cribl, Anvilogic, Proofpoint, and Deloitte, to normalize telemetry into open formats and deliver services, and Delta Sharing lets partners exchange threat intelligence without moving data.
The ecosystem cuts both ways. Partners extend Lakewatch's reach, but the same openness means detection content and services also arrive from those partners, so Lakewatch is the platform others feed rather than infrastructure other security products depend on to run.
Lakewatch's domain credibility comes largely from two launch acquisitions. SiftD.ai, founded by the creator of Splunk's Search Processing Language and lead architects of its search stack, brings large-scale detection engineering, and Antimatter, from UC Berkeley researchers, brings provably secure authorization for AI agents.
Databricks supplies the platform engineering. The organization that built and runs Unity Catalog and the lakehouse at scale provides the data infrastructure Lakewatch sits on, a demonstrated ability to operate governance and analytics at petabyte scale.
The combined team is new. Databricks announced both acquisitions with the March 2026 launch and the specific individuals are unnamed in the cited sources, so the pedigree is verifiable but the group's only security product together is the preview-stage Lakewatch itself.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Databricks Lakewatch product page “The agentic SIEM built for machine speed defense. Transform your SOC with unlimited, unified data, petabyte scale and swarms of agents.” | official | 2026-06-30 |
| s2 | Databricks: Announcing Lakewatch, a new agentic SIEM “Anthropic's Claude models help power Lakewatch, using Claude's advanced reasoning capabilities to correlate signals across security, IT, and business data to surface threats faster.” | official | 2026-06-30 |
| s3 | Databricks newsroom: Databricks Enters Security Market with Lakewatch (March 24, 2026) “Enterprise organizations use Lakewatch to unify their data and detect threats faster with AI. Lakewatch customers include industry leaders like Adobe and Dropbox.” | official | 2026-06-30 |
| s4 | Cloud News: Databricks Enters Cybersecurity with Lakewatch, Its New Agent-Based and Open SIEM “Databricks has decided to fully enter the cybersecurity market with the launch of Lakewatch, a new platform that the company describes as an open and agentic SIEM.” | press | 2026-06-30 |
| s5 | OpenClawAI: Databricks Lakewatch Review, The First Agentic SIEM (RSAC 2026) “The SIEM market is being rebuilt around agents. Lakewatch, Google's Agentic SOC, CrowdStrike's Charlotte AI, SentinelOne's Purple AI, every major security platform is shipping AI agents for detection and response.” | press | 2026-06-30 |
| s6 | NewDecoded: Databricks enters security market with Lakewatch, a new open and agentic AI SIEM “SiftD.ai brings architectural expertise from the original creators of Splunk's search technology. Antimatter provides a provably secure framework for AI agents.” | press | 2026-06-30 |
| s7 | Databricks newsroom: Databricks Agrees to Acquire Panther (June 16, 2026) “Databricks, the Data and AI company, today announces intent to acquire Panther, a leading AI SOC platform. Panther is the third security acquisition announced by Databricks.” | official | 2026-06-30 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Databricks Lakewatch product page “Use Unity Catalog to govern your entire estate in a single place, eliminating silos and vendor lock-in while providing full context for investigations without ever moving your data.” | official | 2026-06-30 |
| s2 | Databricks: Announcing Lakewatch, a new agentic SIEM “Anthropic's Claude models help power Lakewatch, using Claude's advanced reasoning capabilities to correlate signals across security, IT, and business data to surface threats faster.” | official | 2026-06-30 |
| s3 | Databricks newsroom: Databricks Enters Security Market with Lakewatch (March 24, 2026) “Enterprise organizations use Lakewatch to unify their data and detect threats faster with AI. Lakewatch customers include industry leaders like Adobe and Dropbox.” | official | 2026-06-30 |
| s4 | Cloud News: Databricks Enters Cybersecurity with Lakewatch, Its New Agent-Based and Open SIEM “Databricks has decided to fully enter the cybersecurity market with the launch of Lakewatch, a new platform that the company describes as an open and agentic SIEM.” | press | 2026-06-30 |
| s5 | OpenClawAI: Databricks Lakewatch Review, The First Agentic SIEM (RSAC 2026) “Store petabytes of full-fidelity security telemetry in your own cloud storage (Delta Lake or Apache Iceberg). No vendor lock-in, no ingestion tax. Databricks claims up to 80% lower TCO compared to legacy SIEMs.” | press | 2026-06-30 |
| s6 | NewDecoded: Databricks enters security market with Lakewatch, a new open and agentic AI SIEM “SiftD.ai brings architectural expertise from the original creators of Splunk's search technology. Antimatter provides a provably secure framework for AI agents.” | press | 2026-06-30 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.